XenForo news

XenForo security patches for 2.2 and 2.3: which one to install

XenForo released a security patch for every version from 2.2.0 to 2.3.12, then a cumulative round two days later. Which one your forum needs.

D.C Style · 6 min read
Share on X
On this page

On September 7, 2026, XenForo released a security patch for every version from 2.2.0 to 2.3.12, along with XenForo 2.3.13. Two days later it replaced the patches with cumulative ones. If your forum runs anything older than 2.3.13, install this XenForo security patch soon. This post shows which one fits your forum.

What XenForo fixed in September 2026

The patches fix 14 security issues. Marco Paciaroni (BomboBombone) found them and reported them to XenForo through VulnCheck. XenForo Media Gallery got fixes at the same time.

What each issue could allow depends on your version, the features you use, your settings and what an attacker can already do on your forum. XenForo's announcement lists these risks:

  • Actions a user shouldn't be allowed to take.
  • Exposure of information that should stay private.
  • Cross-site scripting.
  • Requests sent from your server to other addresses.
  • Reuse of security tokens.
  • Denial of service.
  • In one specific admin workflow, running arbitrary code.

The announcement doesn't say which issue affects which feature. So treat every forum as affected until it's patched.

Which XenForo security patch your forum needs

XenForo did something unusual this time. Instead of asking everyone to upgrade, it re-released every version since 2.2.0 with a patch. If you run 2.2.9, for example, you can install 2.2.9 Patch 1. You don't need to renew your license for it.

Start with the exact version you run. Our guide on how to find your XenForo and PHP version shows where to look. Then find your case below.

You already run XenForo 2.3.13

You're covered. XenForo 2.3.13 includes all 14 fixes. The cumulative round from September 9 doesn't apply to it.

You run 2.3 and your license is active

Upgrade to 2.3.13. XenForo recommends it over the patch, because it also brings the usual bug fixes. New releases are free to download while your license is active. The one-click upgrade in your Admin CP is the simplest way to do it.

You run 2.2, or your license has lapsed

Install the XenForo security patch that matches your current version. The patch keeps you on the same version. So it doesn't change which add-ons you can run, and you can plan the move to 2.3 later.

You use XenForo Cloud

There's nothing to do. XenForo patched Cloud forums with a modified 2.3.11 build, and they stay on 2.3.11. XenForo also said it would schedule 2.3.13 for Cloud customers.

Why a second round came two days later

The first patches had a gap. Some forums had applied earlier security fixes by hand, as small patches rather than full upgrades. The new patch builds didn't always include those older fixes.

XenForo gave an example. A forum on 2.3.6 should already have applied the fixes from 2.3.7, 2.3.9 and 2.3.10 by hand. Yet 2.3.6 Patch 1 only added the new fixes from 2.3.13. Applying several old patches again by hand is fiddly and easy to get wrong.

So on September 9, XenForo re-released the affected patches as cumulative builds. For example, 2.3.6 Patch 2 includes every security fix from 2.3.7, 2.3.9, 2.3.10 and 2.3.13. XenForo says future security releases will build on these cumulative versions.

Warning:

If you installed a XenForo security patch on September 7 or 8, look for a newer patch for your version from September 9. If there is one, install it too.

How to install it safely

  1. Back up the database and files first. Our guide on how to back up your forum covers both.
  2. Use the one-click upgrade in your Admin CP where it's offered. Otherwise, download the release for your version from the XenForo customer area.
  3. If you upload files by hand, upload every file, then open /install/ on your forum to run the upgrader.
  4. Afterwards, run a file health check to confirm every file arrived.

If you move to 2.3.13

XenForo 2.3.13 also changes four public templates: bb_code_tag_url_unfurl, featured_content_item, lightbox_macros and trending_content_item_thread. If your style customizes any of them, merge the changes under Appearance > Outdated templates.

The 2.3.13 release notes list a few other fixes too:

  • A workaround for a Chromium issue that applied text color unexpectedly.
  • Formatting now survives quoting and pasting.
  • Phrase development output is kept when an add-on's data is deleted.

Coming from 2.2? XenForo 2.3 needs PHP 7.2 or newer, with PHP 8.3 recommended, and MySQL 5.7 or newer. XenForo's official add-ons all require 2.3.

After you patch, check the forum as a member

Patch releases are small, but test the pages your members use most. Post a reply, upload an attachment and open a few forums. Then check Logs > Server error log for anything new.

Some problems only show up for regular members, because staff accounts can see and do more. The quickest check is to browse as a member for a few minutes. Our free Login As User add-on lets staff switch into a member's account without their password. Every switch is logged and ends on its own. It needs XenForo 2.3.

Common questions

Do I need an active license to get the fix?

No. The patch release for your current version is free without renewing. You need an active license to download new versions, such as 2.3.13.

Will the patch break my add-ons?

It shouldn't. A XenForo security patch stays on the same XenForo version, so add-ons that ran on it should keep working. Still, back up first and check your busiest pages afterwards.

Is Media Gallery affected?

Yes. XenForo released Media Gallery updates alongside each round of patches. Update it at the same time as XenForo itself.

What to do next

  • Check your exact XenForo version today.
  • Install the matching XenForo security patch, or upgrade to 2.3.13 if your license is active.
  • If you patched on September 7 or 8, look for the cumulative patch from September 9.
  • Browse the forum as a member and check the server error log.

Not sure which release fits your forum? Open a support ticket with your version, and we'll point you to the right one.

Sources